I used this how-to to configure VPN users that are locally defined in ISE (non-AD users). The only difference that I have made was, that I didn't defined Device admin policy but I created two Policy sets: One for Duo proxy RADIUS and one for ASA TG. ...